Privacy Policy — ra'i
Effective date: [DATE OF LAUNCH]
Last updated: 19 September 2026
ra'i ("ra'i", "we", "us") is a social shopping app, available as an iOS app, on the web at rai.style, and through our companion browser extension. It is operated by Tania Makarem, an individual based in Lebanon (operator details will be updated if and when a legal entity is formed).
This policy explains what personal data we collect, why we collect it, where it is stored, who processes it on our behalf, and what rights you have. We have tried to write it in plain language.
Contact for anything privacy-related: support@rai.style
1. What ra'i does (in one paragraph)
ra'i lets you save products you are considering buying, organize them into catalogs, ask friends for their opinion, get AI shopping advice, and track prices before you purchase. Nothing is sold inside the app: when you buy something, you do so on the retailer's own website, entirely outside ra'i. We collect no payment information and show no advertising. We use product analytics to understand how ra'i is used and to improve it (section 3), and we may earn a commission from retailers when you buy through links in ra'i (section 8).
2. Data you give us
Account and profile data
- Email address and password. Your password is hashed by our authentication provider; we never see or store it in plain text.
- Username and display name.
- Profile photo (if you upload one), bio, country, and city (typed by you — we do not track your location).
- Phone number (optional; not used for login — it lets friends who have your number in their contacts find you, see section 5).
- Birthdate (used for the birthday gift-list feature).
- Currency preference, interests (used to personalize your Explore feed), and app settings (theme, notification and privacy preferences, and similar).
- Optional "fit profile": gender, clothing/shoe/waist/ring sizes, and size-region preferences. You choose whether to provide any of this.
- Your referral code and any referral connections between you and other users.
Content you create
- Items you save: title, product link, photos (uploaded by you or fetched from the product page), merchant, price, description, and attributes such as brand, color, material, sizes, product codes, and category, plus their bought/skipped status.
- Catalogs: names, descriptions, cover images, and which items are in them.
- Chat messages in 1:1 and group conversations, including photos, items, catalogs, and profiles you share into chats. You can edit or delete your own messages.
- Votes ("verdicts"), reactions (likes/passes), public comments, and comment likes.
- Gift-list claims (which are hidden from the person whose gift it is).
- Purchase amounts you mark as bought, used only for your own private spending chart.
- Your conversations with the AI shopping assistant, which are saved to your account so you can return to them. You can delete an assistant chat at any time.
- Reports, mutes, and blocks you submit.
- Messages you send through the in-app "Contact us" form (delivered to support@rai.style by email, with your address as the reply-to).
3. Data collected automatically
- Product analytics: we use PostHog (hosted in the EU) to understand how ra'i is used — which screens and pages are viewed, and key actions such as saving an item (with the store's web address), asking friends, voting, asking the AI assistant, sharing a catalog, and sending a message. These events are linked to your account ID only — never your email, name, or phone number. We do not sell analytics data or use it for advertising.
- Web performance: Vercel Web Analytics and Speed Insights measure page views and loading speed on rai.style without cookies.
- Error reports: when something breaks, we record the error, the page or screen, your device or browser type, and your account ID, so we can fix it.
- Store-link taps: when you tap "open listing", we record which item you opened and when. If you are not signed in, a random identifier stored in your browser is used instead of an account.
- Push notifications: if you allow notifications in the iOS app, we store your device's push token so we can deliver them through Apple's push service.
- Server logs: our hosting providers keep standard, short-lived server logs (which include IP addresses) as part of operating any web service.
We do not use location tracking, device fingerprinting, or advertising identifiers.
Camera and photos: camera and photo-library access is requested only when you choose to photograph or upload an item or send a photo in a chat. No video is ever recorded. How item photos are processed is described in sections 6 and 9.
4. Cookies and local storage
- Essential cookies: the session cookies needed to keep you signed in on rai.style.
- No analytics or advertising cookies: our analytics on rai.style run without cookies.
- Affiliate links: affiliate links are not in use today. If we enable them, tapping through from ra'i to a retailer may cause our affiliate network to set a cookie on its own domain so the retailer knows ra'i referred you. Nothing is set just by browsing ra'i.
- Local storage: your browser or device stores interface preferences (such as theme and recent searches) and, if you are not signed in, the random identifier described in section 3.
5. Finding friends from your contacts
In the iOS app you can choose to find friends from your contacts. If you allow contact access, the app takes the last 8 digits of each phone number in your address book and turns them into a one-way scrambled code (a SHA-256 hash) on your phone. Only these codes are sent to our server, where they are compared against the same codes made from ra'i members' phone numbers. Your contacts' names and phone numbers never leave your phone, and we do not store the codes after the check. Contact access is optional — you can use ra'i without it and revoke it at any time in your iPhone settings.
6. How we use your data (and our legal bases)
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Providing the service: your account, catalogs, chats, votes, notifications | Account, profile, and content data; push tokens | Performance of a contract |
| Importing product details from a link you save and tracking prices of your saved items | The product links you save | Performance of a contract |
| Answering your questions in the AI shopping assistant, including reading product pages and searching the web | Your assistant messages and the relevant saved items | Performance of a contract |
| Identifying products in your photos, and checking that photos are appropriate | Item photos | Performance of a contract; legitimate interests (keeping the service safe) |
| Finding friends from your contacts | Scrambled codes of your contacts' numbers (not stored) | Consent (you choose to use it) |
| Showing official brand accounts how people respond to their products | See section 7 | Legitimate interests |
| Personalizing your Explore feed | Your chosen interests and activity within the app | Legitimate interests (showing you relevant content) |
| Product analytics and error reports | Usage events and error details, linked to your account ID | Legitimate interests (improving and fixing ra'i) |
| Affiliate commissions | The fact that you opened a retailer's page from ra'i | Legitimate interests (funding ra'i) |
| Birthday gift-list features | Birthdate | Performance of a contract (you enable the feature) |
| Sending account emails (signup confirmation, password reset, email-change confirmation) | Email address | Performance of a contract |
| Responding to support requests | Your message and email address | Legitimate interests |
| Safety: handling reports, enforcing blocks, removing content that violates our Terms | Reports, content, account data | Legitimate interests (keeping the service safe) |
We send no marketing emails. If we ever introduce them, we will ask for your consent first.
We do not use your data for automated decision-making with legal or similarly significant effects, and we never sell your data to anyone.
7. Who can see what (visibility of your content)
- Private catalogs and items are visible only to you.
- Shared catalogs are visible to the members you invite.
- Published catalogs are visible to any logged-in user through the Explore feed and through share links (rai.style/c/...). When you publish a catalog, the items in it, your name, username, and profile photo, and per-item "added by" attribution become visible across the app. Publishing always requires your explicit confirmation.
- Profiles have three levels of visibility: a limited public view, a fuller view for friends, and your own full view. Connection-privacy settings let you control parts of this.
- Chats are visible only to their participants. Votes cast in chats, and the playful "influence titles" derived from them, are shown to friends according to the rules described in the app.
- Official brand accounts: when you love, pass on, save, or open the store link of an official brand account's product, that brand can see your name, username, and profile photo next to that activity in its insights. Brands never see your individual purchases — only totals. You can stay anonymous to brands at any time by turning off "Show my name to brands" in Settings; your activity then counts only in anonymous totals.
- Blocked users cannot see each other's public content.
Please think before you publish: anything in a published catalog can be seen by any user of the app.
8. Affiliate links
Some links from ra'i to retailers are affiliate links. When you tap "open listing" and then buy from that retailer, the retailer may pay ra'i a small commission — at no extra cost to you. To make this work, the link passes briefly through an affiliate network, which lets the retailer know the visit came from ra'i. We do not share your name, email, or account with that network or with the retailer. Affiliate links are not in use today. If that changes, we will name our affiliate partner in this policy before the first commission link goes live. What ra'i shows you — including the AI assistant's answers — is never influenced by whether a store pays a commission.
9. The AI shopping assistant and photo features
Messages you send to the AI assistant (the private assistant chat only — never your conversations with friends) are processed by Anthropic (the Claude API) to generate responses. To answer, the assistant may read the product pages of relevant items, search your own saved items, and send search queries to Serper (a web-search provider). Item photos are also sent to Anthropic to read product details and to check that photos are appropriate, and photo links may be sent to Google Cloud Vision and Serper to identify the product. Under Anthropic's API terms, data sent to the API is not used to train Anthropic's models by default. (Lawyer to verify current Anthropic API terms at time of launch.)
Treat the assistant as a shopping companion, not an oracle: its answers can be wrong or out of date.
10. Third parties that process data for us
We share data only with the service providers below, only so they can perform their function, and never for advertising.
| Provider | What they do | What reaches them | Where |
|---|---|---|---|
| Supabase | Database, authentication, and image storage | Your account, profile, and content data | EU (Frankfurt, Germany) |
| Vercel | Application hosting, Web Analytics, and Speed Insights | All app traffic; transient request logs including IP addresses; cookieless page metrics | EU (Frankfurt) and global CDN |
| PostHog | Product analytics | Usage events linked to your account ID (no email, name, or phone) | EU |
| Apple (Push Notification service) | Delivers push notifications to the iOS app | Your device's push token and the notification content | Global |
| Resend | Sends our account emails | Your email address and the contents of those emails | EU (eu-west-1) |
| Google Workspace | Our support mailbox | Support emails you send us | Google infrastructure |
| Anthropic | Powers the AI assistant; reads product details and categories; checks photos are appropriate | The text of your assistant messages; item text and item photos | United States |
| Serper | Web, shopping, and image search for the assistant and photo detection | Search queries and photo links (no account identity) | United States |
| Google Cloud Vision | Identifies products in photos | Photo links (no account identity) | Google infrastructure |
| Zyte | Extracts product details from links you save; performs scheduled price checks | The product URL (no account identity) | — |
| Google Fonts | Serves the fonts on rai.style | Your IP address, as part of a standard web request | Google infrastructure |
When you save an item, the retailer receives nothing from ra'i: we fetch its public product page on our own servers. When you open a retailer's page through an affiliate link, the retailer learns that the visit came from ra'i.
11. International data transfers
Your data is primarily stored in the European Union (Frankfurt, Germany). Some of our providers are located in the United States or operate globally, as shown above. Where data is transferred out of the European Economic Area, we rely on our providers' data processing agreements incorporating the European Commission's Standard Contractual Clauses. (Lawyer to confirm transfer language for each processor at launch.)
12. How long we keep data
Your data is kept for as long as your account exists. When you delete your account (Settings → delete account), your account and everything attached to it — profile, items, catalogs, messages, votes, comments, assistant chats, and push tokens — are permanently and irreversibly deleted. This is a hard delete, not a deactivation. At the same moment, your error reports and store-link taps are anonymized (they no longer point to you). Analytics events, which are linked only to an account ID, are kept for up to 12 months and then deleted; you can ask us to delete them sooner. Residual copies in encrypted backups expire on our providers' standard backup cycles.
If you delete individual content (an item, message, comment, or assistant chat), it is removed at that time.
13. Your rights
You can do most of this yourself, directly in the app:
- Access and correct your data: your profile and content are editable in the app at any time.
- Delete individual content, or your entire account (permanent).
- Change your email with confirmation sent to both addresses and a revert window.
- Stay anonymous to brands with the "Show my name to brands" setting.
- Turn off notifications, and revoke camera, photo, or contact access, at any time in your iPhone settings.
In addition, depending on where you live (including under the GDPR), you have the right to:
- Receive a copy of your data (data portability). Email support@rai.style and we will provide your data in a machine-readable format.
- Object to or restrict certain processing (including analytics), and withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
We will respond to rights requests within one month. We may need to verify that a request genuinely comes from the account holder before acting on it.
14. Age requirement
ra'i is for users aged 16 and over. We do not knowingly collect data from anyone under 16. If we learn that an account belongs to someone under 16, we will delete it. If you believe a child is using ra'i, contact support@rai.style.
15. The iOS share extension and browser extension
The ra'i share extension (in the iOS share sheet) and the ra'i browser extension (Chrome and Safari) send data only when you choose to save: the product page you are sharing or viewing (its URL and product details) is sent to your own ra'i account. They do not track your browsing, do not run analytics, and send nothing anywhere until you actively save a product.
16. Security
Passwords are hashed, traffic is encrypted in transit (HTTPS), sign-in tokens on your iPhone are kept in the iOS Keychain, and data access in the app is enforced at the database level (for example, blocked users are excluded within the queries themselves). No internet service can promise perfect security, but we collect little, share less, and sell nothing — the best security is not holding data we don't need.
17. Changes to this policy
If we change this policy in a meaningful way, we will notify you in the app before the change takes effect. The "last updated" date at the top always reflects the current version.
18. Contact
Questions, requests, complaints: support@rai.style
[LAWYER REVIEW ITEMS: (1) operator/legal-entity block once entity is formed; (2) EU representative / Art. 27 GDPR question; (3) confirm transfer mechanism language per processor; (4) verify Anthropic API training terms; (5) confirm analytics on legitimate interests without a consent banner is acceptable for EU users given cookieless, account-ID-only analytics; (6) affiliate disclosure wording per the FTC/ASA and local rules.]




